The State of Email & DNS Security Across Australian Organisations
4,633 Australian organisations across five sectors, assessed using publicly observable DNS and registry data, September 2026.
This report examines the published DNS, email-authentication, and registry records of 4,633 Australian organisations across five sectors. The headline finding: 45% have no published DMARC record at all, meaning there is no policy published by the domain owner telling receiving mail systems how to handle messages that fail domain authentication, the mechanism behind email spoofing. Most still publish an SPF record, but without a DMARC policy, there's nothing instructing receiving systems what to do when a message fails that check.
No published DMARC record, by sector
| Sector | Organisations checked | No DMARC record |
|---|---|---|
| Health | 2,756 | 48.2% |
| Trades | 562 | 45.2% |
| Real Estate | 598 | 44.1% |
| Legal | 305 | 39.3% |
| Finance | 412 | 29.4% |
Non-intrusive, DNS and registry data only
Every check in this study is a DNS lookup, a Certificate Transparency log query, or a public WHOIS/RDAP lookup: the same information any member of the public can query about any domain. No email was sent, no website was probed, no mail server was contacted. The population was sourced from OpenStreetMap business listings with an associated website, nationwide: every organisation identifiable from that public dataset was checked, not a drawn sample. Data was collected between 23 and 30 September 2026.
Want the full report?
The full report includes the complete per-sector breakdown (SPF, DKIM, CAA, dangling MX records), DMARC enforcement posture by sector, cross-check correlations, the full methodology, and sampling limitations.
Request a copy